Welcome, Guest. Please login or register.

Author Topic: AmiSSL / OpenSSL updates to support TLSv1.1/1.2?  (Read 7015 times)

Description:

0 Members and 1 Guest are viewing this topic.

Offline kolla

Re: AmiSSL / OpenSSL updates to support TLSv1.1/1.2?
« on: October 24, 2014, 10:02:36 AM »
Amiga systems are not suited for Internet anyways. With no development or even interest whatsoever in modernising the IP stacks, and with a software suite that is stuck in mid 90ies and close to impossible to update due to status of source code and licenses - why bother.
B5D6A1D019D5D45BCC56F4782AC220D8B3E2A6CC
---
A3000/060CSPPC+CVPPC/128MB + 256MB BigRAM/Deneb USB
A4000/CS060/Mediator4000Di/Voodoo5/128MB
A1200/Blz1260/IndyAGA/192MB
A1200/Blz1260/64MB
A1200/Blz1230III/32MB
A1200/ACA1221
A600/V600v2/Subway USB
A600/Apollo630/32MB
A600/A6095
CD32/SX32/32MB/Plipbox
CD32/TF328
A500/V500v2
A500/MTec520
CDTV
MiSTer, MiST, FleaFPGAs and original Minimig
Peg1, SAM440 and Mac minis with MorphOS
 

Offline kolla

Re: AmiSSL / OpenSSL updates to support TLSv1.1/1.2?
« Reply #1 on: October 24, 2014, 04:17:20 PM »
What splendid company? Much? My profession is system and network administrator for an NREN, I have a pretty good idea about which operating systems that have active developed and maintained IP stacks and which do not. The Amiga stacks are so way behind that it is not even funny.
B5D6A1D019D5D45BCC56F4782AC220D8B3E2A6CC
---
A3000/060CSPPC+CVPPC/128MB + 256MB BigRAM/Deneb USB
A4000/CS060/Mediator4000Di/Voodoo5/128MB
A1200/Blz1260/IndyAGA/192MB
A1200/Blz1260/64MB
A1200/Blz1230III/32MB
A1200/ACA1221
A600/V600v2/Subway USB
A600/Apollo630/32MB
A600/A6095
CD32/SX32/32MB/Plipbox
CD32/TF328
A500/V500v2
A500/MTec520
CDTV
MiSTer, MiST, FleaFPGAs and original Minimig
Peg1, SAM440 and Mac minis with MorphOS
 

Offline kolla

Re: AmiSSL / OpenSSL updates to support TLSv1.1/1.2?
« Reply #2 on: October 25, 2014, 11:24:17 PM »
You have any documentation about Apple not using IPv6 as default? I have had my Apple products on IPv6 only networks, and it worked fine, by default, out of the box.

Your dreamy ISP box is not happening anytime soon, the marked for such a device is not big enough and these days transition protocols are all about making the IPv4 world available for IPv6 only devices - _not_ the other way around, like you suggest!

How do you plan to map the vast number of IPv6 addresses out in the world to the small number of IPv4 addresses behind your magic router?

And no, it is not just IPv6 that lacking, there is also basic stuff like working path MTU discovery, anything doing with multicast (MiamiDx has a little), a whole range of DNS related issues, ancient DHCP implementations...
B5D6A1D019D5D45BCC56F4782AC220D8B3E2A6CC
---
A3000/060CSPPC+CVPPC/128MB + 256MB BigRAM/Deneb USB
A4000/CS060/Mediator4000Di/Voodoo5/128MB
A1200/Blz1260/IndyAGA/192MB
A1200/Blz1260/64MB
A1200/Blz1230III/32MB
A1200/ACA1221
A600/V600v2/Subway USB
A600/Apollo630/32MB
A600/A6095
CD32/SX32/32MB/Plipbox
CD32/TF328
A500/V500v2
A500/MTec520
CDTV
MiSTer, MiST, FleaFPGAs and original Minimig
Peg1, SAM440 and Mac minis with MorphOS
 

Offline kolla

Re: AmiSSL / OpenSSL updates to support TLSv1.1/1.2?
« Reply #3 on: October 26, 2014, 02:04:42 AM »
The ignorance here is frustrating, would be nice if people could read up on the topic.

Yes, any dual stack implementation prioritize IPv6 over IPv4 - that is how it is supposed to work - a host does DNS lookup and if AAAA record exists, that will be used first, and if connection fails it will try the A record. OSX for a long time chose any record it received first from the lookup, but they have fixed that. Smaller devices should not have the overload of full dual-stack, so DS-lite (yeah, ha ha) was developed, that helps them reach IPv4 hosts even though they are primarly IPv6 only.

Any device that is dual stack is also ready to be IPv6 only, and since IPv4 address space is nothing short if being used up, and the IPv4 routing tables get bigger and bigger due to the fragmentation, IPv6 more and more emerges as the cheap and easy way out - when that happens it is bye-bye IPv4 for most ISPs.

NAT wont help you squat, there is NAT64 that today helps people to run IPv6 only LANs to reach IPv4 services, which many wireless providers already do, especially ar universities where thousands and thousand of devices are hooked up at once. Other likely IPv6 devices are cable TV boxes, I know ComCast at least are working a lot with IPv6 in their TV boxes.

My major point is this - the day your ISP says "%&$#?@!%&$#?@!%&$#?@!%&$#?@!it, enough of this IPv4 legacy crap", you are screwed, ISPs can easily flip over night and vast majority of users will not notice. You see, this is how the teansition is meant to work! And no, they will not develop a special magic router just for us retro fans.
B5D6A1D019D5D45BCC56F4782AC220D8B3E2A6CC
---
A3000/060CSPPC+CVPPC/128MB + 256MB BigRAM/Deneb USB
A4000/CS060/Mediator4000Di/Voodoo5/128MB
A1200/Blz1260/IndyAGA/192MB
A1200/Blz1260/64MB
A1200/Blz1230III/32MB
A1200/ACA1221
A600/V600v2/Subway USB
A600/Apollo630/32MB
A600/A6095
CD32/SX32/32MB/Plipbox
CD32/TF328
A500/V500v2
A500/MTec520
CDTV
MiSTer, MiST, FleaFPGAs and original Minimig
Peg1, SAM440 and Mac minis with MorphOS
 

Offline kolla

Re: AmiSSL / OpenSSL updates to support TLSv1.1/1.2?
« Reply #4 on: October 26, 2014, 02:08:21 AM »
Fittefaen, when did amiga.org start with sensoring, how utterly lame.
B5D6A1D019D5D45BCC56F4782AC220D8B3E2A6CC
---
A3000/060CSPPC+CVPPC/128MB + 256MB BigRAM/Deneb USB
A4000/CS060/Mediator4000Di/Voodoo5/128MB
A1200/Blz1260/IndyAGA/192MB
A1200/Blz1260/64MB
A1200/Blz1230III/32MB
A1200/ACA1221
A600/V600v2/Subway USB
A600/Apollo630/32MB
A600/A6095
CD32/SX32/32MB/Plipbox
CD32/TF328
A500/V500v2
A500/MTec520
CDTV
MiSTer, MiST, FleaFPGAs and original Minimig
Peg1, SAM440 and Mac minis with MorphOS
 

Offline kolla

Re: AmiSSL / OpenSSL updates to support TLSv1.1/1.2?
« Reply #5 on: October 26, 2014, 02:18:50 AM »
My point is that, since noone even cares about fixing the situation of the IP stack, I see little point in fixing the SSL situation. And regardless, AmigaOS was not developed with security in mind - _any_ crypting solution on Amiga systems is nothing but FAIL, since any program can sniff around anywhere in the memory. I don't know if MorphOS or OS4 developers take measures, using MMU for example, to sandbox and protect memory where decryptet data is stored, but for sure on AmigaOS this is not the case.
B5D6A1D019D5D45BCC56F4782AC220D8B3E2A6CC
---
A3000/060CSPPC+CVPPC/128MB + 256MB BigRAM/Deneb USB
A4000/CS060/Mediator4000Di/Voodoo5/128MB
A1200/Blz1260/IndyAGA/192MB
A1200/Blz1260/64MB
A1200/Blz1230III/32MB
A1200/ACA1221
A600/V600v2/Subway USB
A600/Apollo630/32MB
A600/A6095
CD32/SX32/32MB/Plipbox
CD32/TF328
A500/V500v2
A500/MTec520
CDTV
MiSTer, MiST, FleaFPGAs and original Minimig
Peg1, SAM440 and Mac minis with MorphOS
 

Offline kolla

Re: AmiSSL / OpenSSL updates to support TLSv1.1/1.2?
« Reply #6 on: October 26, 2014, 03:02:54 PM »
Of course, I'm just saying that a browser running on an amiga like system is an easy target for abuse, even when https is used.

Regarding IPv6, I checked with peers on an IPv6 forum to make sure there's nothing I have overlookef, and they all agree with me. Only solution would be a stateful NAT46/DNS46 implementation, something that has not been done yet, and it would be very cumbersome and inpractical since you simply cannot map 128bit address space into a 32bit address space. And do no expect ISPs to fix this, they are steadily moving towards IPv6 only to customers, many of them already use IPv6 only for management. It is coming and sooner than you think now.
B5D6A1D019D5D45BCC56F4782AC220D8B3E2A6CC
---
A3000/060CSPPC+CVPPC/128MB + 256MB BigRAM/Deneb USB
A4000/CS060/Mediator4000Di/Voodoo5/128MB
A1200/Blz1260/IndyAGA/192MB
A1200/Blz1260/64MB
A1200/Blz1230III/32MB
A1200/ACA1221
A600/V600v2/Subway USB
A600/Apollo630/32MB
A600/A6095
CD32/SX32/32MB/Plipbox
CD32/TF328
A500/V500v2
A500/MTec520
CDTV
MiSTer, MiST, FleaFPGAs and original Minimig
Peg1, SAM440 and Mac minis with MorphOS
 

Offline kolla

Re: AmiSSL / OpenSSL updates to support TLSv1.1/1.2?
« Reply #7 on: November 09, 2014, 09:25:50 AM »
Olsen, clearly you do not understand that the transition is already happening, and it is IPv4 that is left behind. Here is an example of what is going on...

https://sites.google.com/site/tmoipv6/lg-mytouch
B5D6A1D019D5D45BCC56F4782AC220D8B3E2A6CC
---
A3000/060CSPPC+CVPPC/128MB + 256MB BigRAM/Deneb USB
A4000/CS060/Mediator4000Di/Voodoo5/128MB
A1200/Blz1260/IndyAGA/192MB
A1200/Blz1260/64MB
A1200/Blz1230III/32MB
A1200/ACA1221
A600/V600v2/Subway USB
A600/Apollo630/32MB
A600/A6095
CD32/SX32/32MB/Plipbox
CD32/TF328
A500/V500v2
A500/MTec520
CDTV
MiSTer, MiST, FleaFPGAs and original Minimig
Peg1, SAM440 and Mac minis with MorphOS